Skip to content
RequestGuard Vulnerabilities
Pricing

yiisoft/yii2-dev

Yii PHP Framework Version 2 - Development Package

Composer latest 2.0.55 BSD-3-Clause

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

2.0.55

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

10 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

10

Yii SQL injection vulnerability

Affected range

ECOSYSTEM: introduced 0; fixed 2.0.12.1ECOSYSTEM: introduced 2.0.13; fixed 2.0.13.2ECOSYSTEM: introduced 2.0.14; fixed 2.0.15<2.0.12.1|>=2.0.13,<2.0.13.2|>=2.0.14,<2.0.15

Fixed versions: 2.0.12.1, 2.0.13.2, 2.0.15

Remote attackers could obtain potentially sensitive information from exception messages printed by the error handler in non-debug mode.

Affected range

<2.0.14